Does anyone know of a good tool for analysing Windows authentication logs?

I am in particular looking to find out when a certain user is logging in and out of a computer or the network in general (OWA or VPN), this is for a disciplinary action so I would be looking for a nice easy layout for the results to save any legwork re-presenting them.

2 Replies

You can look through the logs for security on the laptop, this will give you logins on the device. As for network logins these may not show up all the time if the user is using a laptop as they aren't always on the network when they authenticate. You can look at them through the MMC, and I think you can save the event logs as a file which could be sent to management.

From the product description: "Logon Reporter is a purpose-built product that automatically consolidates and archives all types of logon events from all Active Directory domain controllers and provides rich reporting capabilities. The product stores data in a central location and ensures that no events are lost because of log overwrites."

0

This topic has been locked by an administrator and is no longer open for commenting.